Skip to content
SWARE CRM
Documentation Platform

MCP server

Connect an MCP-compatible AI assistant to your CRM, with permissions you approve.

What it is

The CRM runs a remote MCP server. MCP, the Model Context Protocol, is the standard way AI assistants connect to outside tools. Connect an MCP-compatible assistant, such as Claude Code, and it can look things up in your CRM and — if you allow it — create and update records, always within your own permissions.

If you want an assistant inside the CRM itself, that is SWARECO AI. MCP is for assistants that live somewhere else. Both use the same permission-checked tools.

Connecting

The server address is:

https://crm.swareco.com/mcp
  1. Add the server to your assistant using that address. In Claude Code, for example:
    claude mcp add --transport http swareco https://crm.swareco.com/mcp
  2. Your assistant opens a consent page in your browser. Sign in to the CRM if asked.
  3. Read the permissions on the page, untick any you do not want to give, and approve.
  4. Go back to your assistant. It now holds a token for the permissions you approved.

Tokens are short-lived. Your assistant renews them in the background, and you do not sign in again each time.

Permissions you approve

A new connection gets read-only access unless you grant more. The consent page lists every permission your role allows, with the ones the assistant asked for already ticked. Anything that can change data sits in a separate warning panel, and granting any of it needs an extra confirmation tick.

PermissionWhat it allowsWho can grant it
ContactsRead contacts; create new ones and change existing onesRead: everyone. Write: admins and above
OpportunitiesRead deals and the pipeline; create new ones and change existing onesRead: everyone. Write: admins and above
OfferingsRead your products and services; create and change themAdmins and above
AppointmentsRead the appointments you can see; book, change and cancel themEveryone
CommentsRead comments on contacts and deals; add new onesEveryone
FilesList the files on a contact or deal; upload new onesEveryone
AnalyticsRead account-wide KPI and pipeline analyticsAdmins and above. No tool uses it yet

If an assistant later needs a permission it does not hold, it can ask again and you see the consent page for the combined set. Connections made earlier keep exactly what they were granted.

What a connected assistant can do

RecordsTools
Contactscontacts_list, contacts_get, contacts_create, contacts_update, contacts_count
Dealsopportunities_list, opportunities_get, opportunities_create, opportunities_update
Offeringsofferings_list, offerings_get, offerings_create, offerings_update
Appointmentsappointments_list, appointments_get, appointments_create, appointments_update, appointments_cancel
Commentscomments_list, comments_create
Filesdocuments_list, documents_prepare_upload, documents_create
Connectionwhoami — which account the connection belongs to
  • A deal's additional contacts and offerings can be read and set, and contacts and deals can be assigned to a teammate by email address.
  • Cancelling an appointment sets its status to cancelled. The record and its history stay.
  • Comments are plain text. An @ in a comment from an assistant does not notify anyone.
  • Creating or cancelling an appointment sends the usual notifications, as a Calendly booking does.

Uploading a file

File contents are too large to travel inside a tool call, so an upload takes three steps: the assistant asks for a short-lived upload link, sends the file's bytes to that link itself, then attaches the uploaded file to the record. That needs an assistant that can make an HTTP request — Claude Code can; a chat-only assistant cannot.

The attached file goes through the same checks as any upload: content-type allowlist, 25 MB cap and virus scan. Tools return file names and details, never a file's contents. The server never fetches a web address on an assistant's behalf.

What it can never do

  • Delete. There is no delete permission and no delete tool, so no instruction can reach one.
  • Reach another account. Every lookup runs through your account. An identifier from elsewhere is answered exactly like one that does not exist.
  • Change more than one record per call. There is no bulk tool.
  • Go beyond your role. Each call is checked as you, at the moment it is made. If you are demoted, the connection loses that access straight away.

Your role and field permissions apply

  • Fields your role cannot see are left out of what an assistant reads.
  • A write that includes a field your role cannot change is refused as a whole, naming the field.
  • Members read and book only the appointments assigned to them.
  • Contact, deal and offering writes need an admin or above, even though a member can change some of them in the app.

Records and history

Changes made through MCP appear in history as Your Name (MCP), so they are never mistaken for something you typed yourself.

Limits and cautions

  • Rate limits. Write requests are limited per person and per client. A client that hits the limit is told to wait and try again.
  • Create is not safe to retry. If an assistant repeats a create after a timeout, you can end up with two records. Updates set fields to the values given, so repeating them changes nothing further.
  • Treat record text as untrusted. A connected assistant reads whatever is in your records, including text visitors typed into a public form. Connect only assistants you trust, grant write access only when you need it, and check history if something looks off.

For developers

The server uses OAuth 2.1 with PKCE (S256) and publishes its discovery documents at the standard well-known paths. Clients can register with a Client ID Metadata Document, an HTTPS address that describes the client; native clients can use a loopback redirect on any port. It speaks MCP revisions 2026-07-28 and 2025-11-25 over Streamable HTTP, with JSON responses.


Something inaccurate or missing? Tell us — we would rather fix the docs than have you guess.